От: "Atlantic IT Support" <AtlanticITSupport@tomorrowsoffice.com>
Кому: user@withoutemail.com
Дата: 2026-08-19T13:30:12.000Z
✅ TICKET COMPLETED
Your service request has been completed.
Client
Stonehenge Advisors, Inc
Ticket
3615755
Contact
Dan Sablosky (POC)
Summary
[##385591##] High - SentinelOne Threat - Stonehenge Advisors, Inc - Advanced_IP_Scanner_2.5.4594.1.e
Service Complete
Your service request has been completed and will automatically close in one business day. If you believe additional work is needed, simply reply to this email before the ticket closes and we'll be happy to assist.
Work Performed
DiscussionAakash Singh8/17/2026 4:00 PM-4:05 PMConfirmed it was our technician. Also, checked the applications on the machine and it was safe.
No further action required. Closing this ticket now.
Dan Sablosky (POC)8/17/2026 3:59 PM-{ "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://desk.cyflare.cloud/portal/ticket/385600", "name": "View Ticket " }, "description": "View Ticket" }
Dear IH-Atlantic_Stonehenge Advisors,
A ticket has been created with the following details:
Account Name: Atlantic_Stonehenge Advisors
Ticket ID: 385600
Priority: High
Subject: High - SentinelOne Threat - Stonehenge Advisors, Inc - b22c592.rbf - 08/17/26
Description:
EDR: b22c592.rbf
Customer: Stonehenge Advisors, Inc | Detected: 2026-03-19 05:51:17 UTC-04
Priority: HighSource: SentinelOneThreat Status: Mitigated - Contained by SOCkill: success
Alert Link:EDR Alert
Executive Summary AI-Assisted
Suspicious software activity was detected that attempted to access credential stores and establish persistence, impacting a domain user on a Windows endpoint; the incident is rated high severity due to credential exposure and persistence techniques that could allow ongoing access. The activity has been contained by SOC controls and the device is isolated for remediation. Potential business impact includes unauthorized access to sensitive systems, disruption of services, and increased risk of data loss or lateral spread.
SOC Response Actions
Actions the SOC performed (or attempted). Follow this link for further information on Use Case #5 and Use Case #6.
ActionStatus
--- ---
Jennifer, no full disk scan command was sent. Not Configured
Jennifer, endpoint was not isolated from the network. Not Configured
Recommended Remediation
[Containment] Isolate the infected endpoint 'Jennifer' from the network immediately and disable its network interfaces and remote access to prevent further lateral movement.
[Eradication] Quarantine and remove the malicious file located at \Device\HarddiskVolume3\Config.Msi\b22c592.rbf and delete the modified file \Device\HarddiskVolume3\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\ScreenConnect Client (b48902bf944303cd)\user.config from the endpoint.
[Eradication] Terminate and block the process ScreenConnect.ClientService.exe and remove any associated scheduled tasks, services, or persistence mechanisms including application shim entries.
[Hardening] Reset local and domain credentials for accounts with elevated privileges that accessed the affected system and enforce multi-factor authentication for those accounts.
[Hardening] Apply the latest SentinelOne agent and OS security updates to the endpoint, and ensure SentinelOne protections cannot be tampered with by restricting registry and service modification permissions.
Key Details
Threat ClassificationMalwareEndpoint NameJennifer
Detection EngineOn-Write DFI - SuspiciousEndpoint IP Address192.168.12.133
File Path\Device\HarddiskVolume3\Config.Msi\b22c592.rbfSite NameStonehenge Advisors
File Hasha33c975b07fc9db4713b6584965dd88b143d61b99c4d699dd326374b82dcd271 MaliciousGroup NameStonehenge Advisors Inc - Murano Condos
File Publisher NameSentinelOne Mitigation Policyprotect
File Publisher Signed & VerifiedNotSignedSentinelOne Mitigation Statusnot_mitigated
Command Line"?e=Access&y=Guest&h=instance-btrzta-relay.screenconnect.com&p=443&s=49625191-e28b-4d67-af63-79fee495609b&k=BgIAAACkAABSU0ExAAgAAAEAAQDhHfHiGfTR3of9T0p8Jav234%2fjsTqNjm6YvEI3oEF57UIEF9w6KYVSw5iD3h1K0skK5HbKUOefaPSJS1lEtZUDRb9eyfWC%2bh9kQYW10z%2bPyT1DCIGAtAYSQpsOK7WjjI3hiXj9YtcUOxeyWVC2AywSh%2fxgvVvyq%2bVM%2bgdAd67rgo2L1qXFN3jI1Z4YwuJ9vy0focc2dlwHDCgjMxApUBdRtv23aYqkAxl0uE4cjD44Ge%2fxCsdEf9tm0Zya5pWriTlMbjaV4%2f7hCr1l5A2Cq%2fmoIgaIuQKSuerefsXqqcH8KHTcy7JPbIZnPPeC3Yt9al6BKi3E2IGyzFZBy61CVOS8&v=AQAAANCMnd8BFdERjHoAwE%2fCl%2bsBAAAAaxJ9F%2b5eQUKnp7YvXoIcuwAAAAACAAAAAAAQZgAAAAEAACAAAAAUDy9oMYfQZpnjkC%2fgrTnHPq6aaXzMZ5nH2aZwEr6PdgAAAAAOgAAAAAIAACAAAADnv8W6Fr8yDsbaN7fdoao6Hotd8I7VB1eJxmUQ76%2fekaAEAADmaig%2f4y12JB4bP2WgT9AkgN9hlzaMhCHKyc7tFmtpJYzTRknvGh60%2fh8t3paX1Tmw6W4wh0fpaN1rhxAxLNcdfv6JZqKmhjvcQ37%2fDSOhLFgnxQ4CUYTUaQjtKVIPLeucbzaypy1K%2fNB4f49W4XiD6SvOwTBo6KJKc9myV207Rd9isI8sKLET0BjIZ2L2kXtBux%2bRhhYydd10LgvEmt4ynpZyvfiQVF75xVoS9sF3w1v1jAebSTLHSpXrEKhSOL3%2fLdc2g1b%2fTocnyJ0KuLFPHhaDQ2S98ifxrzwvFCtss1p0GdYwNw05eJEEW5%2bBQibgCKECF%2feOx%2fVF47txNz3mpbHoOB90DCqVMvl%2foa0ovca41yk%2b7oEBMa2tYzFNbdOf4HlrRi2i%2bFQuRl4TrE4QNeAW%2fIlFNZBaQZUt53pmXc8wzW5ofHe7jvKMeL9c4cTBm8c%2forTRjPjNuC3efG6oBnzBN2H%2b%2flNKJYGyN227HBaLS4BZlfMQyPOm39lx1q7EUoJdpkGNOvuNGKFBQSdxlOhHkbjFmgbkJyAKzsagJoCdFG5W3Nvk0iKkJrLrAIKyNZLeU%2fXQSogbVtXzo6DWsgqj8AQlF0MmMVdGYqXMb3Tk9rAOCEkvEkZztDHub5pS8OfY0VOSsnHUAzg1LYMEUvPtHUs3PuV68WDHpThtXXTjZdLxK7efIdka3E84CjsWvmsrVAL1DNQds0444dT8EOTDagq78D%2fhTkbLLAb1Cpka3uWo06wwpI2zUBq%2f8%2bR%2bMA1kaOW1Oc%2fQTaKQjWbg0bmG6XAs1DJKsGoHNO9GxGWkyjXp1SHjEXCdfARfh%2bHuI6nxeJ05XVhu7%2fbw6vjZsziMlZQtJA9hZ8XLkRCgEBr65Aa9vSasLK3ClZVrK%2bPHquL610HVH%2bZKRFpy2aXEDwmDf6Yy6lSTjuU%2fQVFH6N8ieDJPHEuAQ5NNRcMZhgFf3Vf6DhcF1RIiWRy8BvYnq2%2fo%2bB2oRUvjFqmtf8vKWv2nFgjaIhGRKUyfLruyQaAT6QUcHPec5CHinCsPqg8K%2bmm0SPruBpzLISLTH1wJHt2f6%2f71aioi8UFXivSUS7Cr4M%2bmoJ3ocxUWGuX6SMXoYnInPoawc%2bq5Q9e82IPOcENv6RdzH3IMT8CI82aZ6wm9UmvNoN8MroQS3FDhNYTKiM11PxdukjuvLlzIevgKM2Rfb4z1%2fXaFH4bVvbP54hDhAKNuYFdlfG0un%2bPZaEHWYGRXIZFKdAiu8gZVocSaaXvzLDwrBi6%2f%2fMMVJfOletGgx%2bcChr82LwlB4X14taj03GhGnHQc%2f0xItvVqEX4WQuw%2baLd9Tm0BHBah2Zaz1pzl2HEAL3kAMo0RSX1kk%2fiypPZm2iEXfXhyrWYK7WOFxHbxMfeE%2f6YU0XFAVPiCc3Pwa0rUf2AqFAzgBwCfI6bpJ1UA%2f18seqNqC9IgS1IGx28KBUQKXqNfTEQtefFmYlANtqf4lntsQyAEnN4P2dUp2xrbtr6tfdq%2bdfRa0zdr5sNudZWWOs0HIDRBGi20kfE%2bNb4auBftdglRHbFtwCIq7qFFiCdnHPTWM9PEQWFA20AAAACrbNKnMW1%2bxX9O50uHjc5W%2bS2aZbeS4%2b7v9tE4setfH7VNf6b%2bJwzDSjRQjHvz5zwnjrrVEzdW7ztjAUV%2byXnR&t=&c=&c=&c=&c=&c=&c=&c=&c="
SOC Findings
Threat Intelligence & Reputation
VirusTotal
a33c975b...82dcd271
Malicious
File hash detected by 9 security engines. Classified under the meaningful name c:\users\Alexander.Villarosa\AppData\Local\Apps\2.0\VYLE4ZBJ.ERD\K8XVK7JY.LRN\scre...exe_27fa83f1ad328157_0019.0009_none_c11767874ab9cb96\ScreenConnect.ClientService.exe.
Hybrid-Analysis
a33c975b...82dcd271
No Relevant Results
No behavioral or reputation data returned for this hash at the time of analysis.
Indicators of Compromise
This summary outlines multiple serious security threats. An application was hijacked by a 'suspicious DLL,' indicating unauthorized manipulation. The 'Static Engine' detected these issues, including suspicious packing of processes and access to Chrome's private memory, which could lead to data theft. A keylogger was installed, and the PowerShell execution policy was changed, allowing harmful scripts to run. Additionally, there were attempts to evade detection by tampering with Event Viewer logs and modifying registry keys. The application registered itself to run persistently through various methods, suggesting a significant risk of ongoing malicious activity that requires immediate attention.
Network Connections
40.160.30.25 (Outbound, Port 443): outbound TLS connection to external IP over HTTPS from ScreenConnect process
40.160.30.26 (Outbound, Port 443): outbound TLS connection to external IP over HTTPS from ScreenConnect process
15.204.154.40 (Outbound, Port 443): repeated outbound HTTPS connections to same external IP (multiple events)
15.204.166.72 (Outbound, Port 443): outbound TLS connection to external IP over HTTPS from ScreenConnect process
15.204.154.40 (Outbound, Port 443): outbound HTTPS connection to external IP from ScreenConnect process
Process Involved
powershell.exe (JqYWJUL_9kOLrun.ps1) (Parent: | Suspicious): Executes ScreenConnect-delivered scripts observed running multiple times.
powershell.exe (FYTed_0G_0etrun.ps1) (Parent: | Suspicious): Root-level PowerShell invoking ScreenConnect script instance during the incident.
powershell.exe (t8sU9aFu20Kwrun.ps1) (Parent: | Suspicious): Another PowerShell process running ScreenConnect script variants tied to the storyline.
powershell.exe (ksvWgs0cp0a-run.ps1) (Parent: | Suspicious): PowerShell instance running unsigned ScreenConnect script code.
advanced_ip_scanner.exe (Parent: | Third-Party Unknown): Network scanning tool observed making TCP connections to internal hosts.
Cross-Service Intelligence i
Below is additional context from other services subscribed by the customer.
ServiceSourceRelevant InsightReference
--- --- --- ---
ESN/ANo relevant tools configured for enrichment.
Need help or want us to take additional actions? Reply to this ticket and the SOC will assist.
You can view all details here: 385600
This email has been scanned by Trustifi Inbound ShieldDan Sablosky (POC)8/17/2026 3:51 PM-{ "@context": "http://schema.org", "@type": "EmailMessage", "potentialAction": { "@type": "ViewAction", "target": "https://desk.cyflare.cloud/portal/ticket/385591", "name": "View Ticket " }, "description": "View Ticket" }
Dear IH-Atlantic_Stonehenge Advisors,
A ticket has been created with the following details:
Account Name: Atlantic_Stonehenge Advisors
Ticket ID: 385591
Priority: High
Subject: High - SentinelOne Threat - Stonehenge Advisors, Inc - Advanced_IP_Scanner_2.5.4594.1.exe - 08/17/26
Description:
EDR: Advanced_IP_Scanner_2.5.4594.1.exe
Customer: Stonehenge Advisors, Inc | Detected: 2026-08-17 15:44:35 UTC-04
Priority: HighSource: SentinelOneThreat Status: Mitigated - Contained by SOCkill: successquarantine: failed
Alert Link:EDR Alert
Executive Summary AI-Assisted
A suspicious, potentially malicious software file was detected and blocked on an employee's laptop used by Jennifer McDonnell; the event is classified as moderately severe because the software exhibits risky behavior and failed automated containment steps. The device is currently protected and mitigation actions were attempted with partial success. Business impact is limited but could include data exposure or disruption to the user’s workflows if similar tools run elsewhere, so continued vigilance is advised.
SOC Response Actions
Actions the SOC performed (or attempted). Follow this link for further information on Use Case #5 and Use Case #6.
ActionStatus
--- ---
Jennifer, no full disk scan command was sent. Not Configured
Jennifer, endpoint was not isolated from the network. Not Configured
Recommended Remediation
[Containment] Isolate the endpoint 'Jennifer' (agentUuid 298b653f5c6449c2afe078fcca2ad79c) from the network and disable its Wi-Fi interface to prevent further lateral discovery activity.
[Eradication] Remove and delete the file \Device\HarddiskVolume3\Users\Jennifer McDonnell\Documents\ScreenConnect\Temp\Advanced_IP_Scanner_2.5.4594.1.exe and any related ScreenConnect temporary installers from the endpoint and quarantine remaining copies using endpoint management tooling.
[Eradication] Terminate and block the originating process ScreenConnect.WindowsClient.exe on the affected host and apply execution prevention for unsigned executables in the ScreenConnect Temp directory via application control/policy.
[Hardening] Enforce application allowlisting and restrict execution from user profile and temp directories via group policy or endpoint protection to prevent similar hacktool execution.
[Hardening] Require the user account Jennifer\Jennifer McDonnell to re-authenticate and, if the account has elevated rights, apply a principle of least privilege review and remove unnecessary local admin privileges.
Key Details
Threat ClassificationMalwareEndpoint NameJennifer
Detection EngineOn-Write DFI - SuspiciousEndpoint IP Address192.168.12.133
File Path\Device\HarddiskVolume3\Users\Jennifer McDonnell\Documents\ScreenConnect\Temp\Advanced_IP_Scanner_2.5.4594.1.exeSite NameStonehenge Advisors
File Hash26d5748ffe6bd95e3fee6ce184d388a1a681006dc23a0f08d53c083c593c193b MaliciousGroup NameStonehenge Advisors Inc - Murano Condos
File Publisher NameFAMATECH CORP.SentinelOne Mitigation Policyprotect
File Publisher Signed & VerifiedNotSignedSentinelOne Mitigation Statusnot_mitigated
Command Line
SOC Findings
Threat Intelligence & Reputation
VirusTotal
26d5748f...593c193b
Malicious
File hash detected by 2 security engines. Classified under the meaningful name Advanced_IP_Scanner_2.5.4594.1.exe.
Hybrid-Analysis
26d5748f...593c193b
Malicious
File hash detected by 3 security engines. Classified under the meaningful name Advanced_IP_Scanner_2.5.4594.1.exe.
Indicators of Compromise
This summary indicates that a tool known as 'Advanced IP Scanner' has been detected on the system. While this tool is often used for legitimate network scanning, its presence can also suggest potential malicious activity, as it may be employed by attackers to identify devices on a network for exploitation. The detection of this hack tool raises concerns about possible unauthorized access or reconnaissance efforts, highlighting the need for further investigation to ensure the security of the network and its devices.
Cross-Service Intelligence i
Below is additional context from other services subscribed by the customer.
ServiceSourceRelevant InsightReference
--- --- --- ---
ESN/ANo relevant tools configured for enrichment.
Need help or want us to take additional actions? Reply to this ticket and the SOC will assist.
You can view all details here: 385591
This email has been scanned by Trustifi Inbound Shield
Thank you,
Need Additional Assistance?
Reply directly to this email or contact our Customer Care team at (212) 507-9420 if you have any questions or if the issue has not been fully resolved.
134 West 26th Street | New York, NY 10001 | ©2026 Atlantic.
View Ticket